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Abstract 

The ability to unconditionally verify the location of a communication receiver would lead to a 
wide range of new security paradigms. However, it is known that unconditional location verification 
in classical communication systems is impossible. In this work wc show how unconditional location 
verification can be achieved with the use of quantum communication channels. Our verification 
remains unconditional irrespective of the number of receivers, computational capacity, or any other 
physical resource held by an adversary. Quantum location verification represents a new application 
of quantum entanglement that delivers a feat not possible in the classical-only channel. For the first 
time, we possess the ability to deliver real-time communications viable only at specified geographical 
coordinates. 
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The ability to offer a real-time communication channel whose viability is unconditionally 
a function of the receiver location would offer a range of new information security paradigms 
and applications. In particular, there are a range of industries and organizations that clearly 
would be interested in delivering information content in the sure knowledge a recipient 
receiver is at an a-priori agreed upon location {e.g. see discussions in |l-4|). The ability 
to guarantee location-sensitive communications requires unconditional (independent of the 
physical resources held by an adversary) location verification. However, in the classical- 
only channel such unconditional location verification is impossible. The finite speed of 
light can only be used to bound the minimum (but not the maximum) range a receiver 
is from some reference station. Add to the mix that classical information can be copied, 
and that an adversary can possess unlimited receivers (each of which can be presumed to 
possess unlimited computational capacity), it is straightforward to see why classical-only 
unconditional location verification is impossible. It is the purpose of this work to show how 
the introduction of quantum entanglement into the communication channel overcomes the 
above concerns, providing for the first time an unconditional location verification protocol. 

Quantum teleportation |5j, the transfer of unknown quantum state information, is now 
experimentally verified through a host of experiments, e.g. In addition, the key 

resource underpinning teleportation, quantum entanglement, has been experimentally ver- 
med over very large ranges. A,r errtanglemerrt measuremerrt over 144U,n. achieved reeerrt.y 
using optical free-space communications between two telescopes [8[, proves the validity of 
ground- station to satellite quantum communications, and is widely seen as a major step 
in the path towards a global quantum communications network. In such a network it is 
envisaged that a combination of satellite and fiber optic links will interconnect a multitude 
of quantum nodes, quantum devices and quantum computers. In optical fiber, transmission 
of entangled photons is limited to about 100km by losses and de-coherence effects, e.g. js]. 
Communications over fiber beyond this range will make use of either quantum repeaters 
|lo| . or the trusted relay paradigm used in a recent deployment of an eight-node quantum 
network [Hj]. 

Experimental verification of quantum superdense coding 12| has also been achieved 



through a series of experiments, e.g. [l3|, [ij]. In superdense coding, two bits of classi- 



cal information can be transferred at the cost of only one qubit. 

Teleportation and superdense coding are strongly related, and indeed they are often 
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considered as protocols which are the inverse of each other, differing only in how and when 
they utilize quantum entanglement. Quantum location verification can be considered a new 
protocol that differs again in how and when it uses quantum entanglement. 

The principal condition for unconditional location verification is that; only a device at one 
unique location (the authorized location) is able to, immediately and correctly, respond to 
signals received from multiple reference stations. In the classical-only channel this condition 
can never be unconditionally guaranteed. However, as we now show, with the introduc- 
tion of quantum communication channels the condition necessary for unconditional location 
verification can in fact be guaranteed. 

Consider some reference stations at publicly known locations, and a device which is not 
a reference station (Cliff) that is to be verified at a publicly known location (x^, y^ ). Let 
us assume that processing times, such as those due to local quantum measurements, are 
negligible (we discuss later the minor impact of this). We also assume that the reference 
stations are authenticated and share secure communication channels between each other via 
quantum key distribution (QKD) 15|, ll6[, and that all classical communication between Cliff 
and the reference stations occurs via wireless channels. The use of wireless communications 
is important since we will require the time delay of all classical communications to be set 
by the hne-of sight- distance between transceivers divided by c (light speed in vacuum). 

For two dimensional location verification we require a minimum of three reference stations. 
Consider maximally entangled multipartite systems available to a network possessing k 
reference stations. Consider also that each of the multipartite systems comprises k qubits, 
with each reference station initially holding one qubit from each of the N systems. The 2^ 
orthogonal basis states of each multipartite state can be written 

\Sb) = ^ (|a)i |a)2 . . . |a)^ ± \a)^ ® \a)^ . . . |a) J (1) 

where b = 1, ...2'^, and the states \a) represent |0) or |1) with the index on the state labelling 
the location (ignoring any null state). 

Transformation between the basis states can be achieved by a set of 2^ unitary transfor- 
mations induced on the locally held qubits. By this means a fc-bit message, per entangled 
state, can be transferred from the stations to Cliff. This is achieved using superdense coding 
in which the stations encode each message to a specific basis state \Sb), with Cliff decoding 
the message via a quantum measurement that deterministically discriminates all possible 
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basis states (the state \Sb) is sent directly to Cliff via quantum channels connected to the 
reference stations). 

Quantum location verification builds on this concept of state encoding with one key 
addition. It must be the case that deterministic discrimination amongst the encoded states 
is possible, within a pre- described time bound at only one location. This can be achieved if 
the 2^ states which encode the k-hit messages are made non- orthogonal by the introduction 
of an additional local unitary transformation at each reference station. Let these additional 
transformations be labelled C/?", where r — 1, ...k indexes the reference station, and i — 1...N 
references the specific multipartite state to which the local transformation is applied. 

Consider the ith encoded multipartite state in which a A;-bit message is encoded as \Sb). 
Then on application of the additional transformations a new state |Tj) = Ul®Ul®...U^ \Si,) 
is produced. Our requirement is that (Tj | Tj) ^ when |Tj) ^ [^j)- Ideally, the uni- 
tary matrices Ul are chosen so that upon measurement of |Tj) in a measurement basis 
l-S*!) , |5'2) . . . |5'2fc), the probability of collapse to each basis state is approximately equal 

For quantum location verification to be unconditional it must be impossible for an ad- 
versary to map the values of U'- to specific k-hit messages (in our protocol all matrices Ul 
and all k-h\i messages are ultimately sent over a classical channel). This means that there 
must be some form of randomness apphed to the selection of each C/f . One strategy that 
provides for both a random selection mechanism, and the required non-orthogonal behavior 
between the states |Ti), is to allow the C/f to be constructed from four random real param- 
eters (a,/?, 7,0). The unitary matrix at each reference station can then be implemented 
as 

U = e''^R,{a)Ry{P)R,{-f), (2) 
where the rotations R are given by 

and with the ex's representing the Pauli operators. Classical communication of the additional 
matrices can be achieved in many ways, such as passing of experimental instructions (e.g. 
duration of laser pulses), indexing of a large number of matrices, or as a transfer of matrix 
element information. The latter, which we adopt here, involves the transmission of the 
values (a,^, 7, 0) adopted for each Ul- Although finite bandwidth of the classical channel 
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limits the precision of this information transfer - required precision is available at the cost of 
additional bandwidth. In actual deployment, any global phase can be ignored. We discuss 
later a pragmatic implementation strategy leading to an outcome effectively the same as the 
outcome derived from Eq. ([2]). 

The location verification proceeds by the encoding of a secret sequence onto a set of 
N entangled systems |Tj=i...Ar), transmission of each |Tj) to Cliff via quantum channels, 
followed by transmission of the unitary matrices f/J" {i.e. the set (a, (3, 7, 0)) to Cliff by clas- 
sical channels. Upon receiving this quantum and classical information Cliff can decode and 
broadcast the decoded sequence via the classical channel. Given that information transfer 
over the classical channel proceeds at a velocity c, location information becomes uncondi- 
tionally verifiable (as explained later). Ultimately, the verification is based on the inability 
to clone deterministically the set |Tj) with fidelity one. Although cloning with lower fidelities 
is possible, confidence levels on the location verification can be increased to any arbitrary 
level by increasing A^. 

We now outline the protocol in more detail using well known maximally entangled states. 
For clarity, we proceed with a one dimensional location verification using just two reference 
stations, which we henceforth refer to as Alice and Bob. A geometrical constraint for one- 
dimensional location verification is that the device to be located must lie between Alice and 
Bob. That is, tac + tbc = 'Tab, where tac {'Tbc) is the light travel time between Alice (Bob) 
and Cliff, and where tab is the light travel time between Alice and Bob. 

Let Alice share with Bob a set of N maximally entangled qubit pairs ^f^'j, where the 
subscript i = 1 . . .N labels the entangled pairs. Let each of the pairs be described by one of 
the Bell states |$^) = ^ (|00) ± |11)), |^^) = ^ (|01) ± |10)), with the first qubit being 
held by Alice and the second by Bob. We will assume an encoding (00 — )■ $^ etc.) that is 
public. 

Without loss of generality we can assume all pairs are initially in the state | After the 
encoding of a sequence onto a series of entangled pairs, Alice and Bob apply an additional 
random unitary transformation Uf and , respectively, to their local qubit from each pair. 
As a consequence, the entangled pairs held by Alice and Bob now form a non-orthogonal 
set, 

rr) = uf®uf\nr) . (3) 
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FIG. 1: Quantum Circuit for Location Verification 



For example, for 1$+) Eq. ([3]) leads to a state ^ (f/^ |0)^ ® f/f |0)^ + U^^ O Uf |1) 
A step-by-step exposition of the protocol follows. 

• Step 1: Via a secure channel Alice and Bob agree on a mutual random bit sequence Sab that 
is to be encoded. The encoding is achieved via superdense coding in which two classical bits 
are encoded using local unitary operators as described by /|$^) = l*^'^), o'x |$^) = |^^), 
iay |$+) = I^P^), and cr^ |$+) = |$^). For each pair of entangled qubits, Alice and Bob also 
agree who will induce the necessary unitary operation on their local qubit in order to encode 
sequential two-bit segments of Sab- 
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• Step 2: Prior to the transmission of any qubit the transformation 
described by Eq. (jSj) is induced. This set is then transmitted by Alice and Bob to Cliff via 
two separate quantum channels. 

• Step 3: Alice and Bob communicate to Cliff, via separate classical channels, the random 
matrices Uf and Uf used to form the set T^^^. This classical information is transmitted 
in a synchronized manner to Cliff such that for each value of i the Uf- sent by Alice and 
the sent by Bob arrive simultaneously at Cliff's publicly announced location (x^,?/^). 
It is also ensured that this classical information is received at Cliff after the arrival of the 
corresponding qubit pair of Tf^^. 

• Step 4: Upon receipt of each matrix pair Uf-, , Cliff undertakes the transform 
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^f^^ before taking a Bell State Measurement (BSM) in order to 
determine the two-bit segment encoded in the entangled pair. Cliff then immediately broad- 
casts (classically) the decoded two-bit segment back to Alice and Bob. 
• Step 5: Alice checks that the sequence returned to her by Cliff is correctly decoded and 
notes the round-trip time for the process. Likewise Bob. Alice and Bob can then compare 
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their round-trip times to Cliff {2tac and 2tbc) in order to verify consistency with Chff's 
pubhcly reported location (x^,?/^,). 

The quantum circuit for the one dimensional quantum location verification just described is 
given in fig. 1. 

Quantum location verification is independent of the physical resources an adversary may 
possess. In the classical-only channel an adversary can place co-operating devices closer to 
reference stations and then delay responses in order to defeat any location verification {e.g. 
2|, Attempts to remedy this problem by making devices unique and tamper-proof are 
clearly limited (see discussion in |2|), and cannot provide for unconditional security. 

However, in quantum verification multiple devices are of no value. In order to decode 
immediately, Cliff's receiver must possess all the qubits that comprise each entangled state. 
Cliff cannot distribute copies of his local qubits to other devices due to the no-cloning 
theorem [l7|. The key point is that for any given location {x^,yy) that is to undergo a 
verification process, one can always find placements for the reference stations such that no 
other location can be simultaneously closer to all of the reference stations than {xy,yv) {e.g. 
recall the geometrical constraint in our one dimensional verification). This being the case, 
an adversary with no device at the location being verified cannot pass the verification test. 
Even if the adversary possess multiple receivers, an additional round-trip communication 
time between his devices will be required for decoding. This will result in a round-trip time 
between at least one reference station and the location being larger than expected. 

In classical verification the round-trip communication between the adversary's devices is not 
required. 

Extension of the one- dimensional location verification protocol to two-dimensional verifi- 
cation could be a straightforward application of additional bipartite entanglement between 
Alice and some third reference station, say Dan. This can be achieved by introduction of a 
new set of Bell states shared between Alice and Dan, with the protocol following a similar 
exposition to that given. However, perhaps a more elegant solution is the use of multipar- 
tite entangled states. For example, consider a Green-Horne-Zeilinger (GHZ) p^, ll9|] state 
in which three qubits are maximally entangled, such as \S)^ = (|000) + |111)). Trans- 
formation from this GHZ basis state to one of the eight basis states is achieved by the set of 
transforms Ughz = {(yz®(yz,h®(^z-,icry®az,(yx®CFz,h®CTx^®ax,(Tx®Ox,i(yy®(yx)-, where 
the first (second) operator acts on the first (second) qubit [22|. A step-by-step quantum lo- 
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cation verification using such tripartite states proceeds in similar manner to the bipartite 
protocol. 

Clearly, a security threat to the protocol is the potential ability of an adversary who is 
in possession of an optimal cloning machine, redistributing the set |Tj) to other devices. If 
cloning were exact, the verification test would fail because the round-trip communication 
between the devices (needed to decode) would not be required. However, optimal cloning 
of the set |Tj) can be described by the fidelity, Fc, between this set and a cloned set. 
This is known to be upper bounded by ~ 0.7 for bipartite entanglement and F^ ~ 0.6 



for tripartite entanglement [20|, |2l|. As such, for a series of two-bit messages encoded in 
= 100 bipartite states, an optimal cloning machine would have a probability of 1 in 10^^ of 
passing the verification system even though not at the authorized location. For 100 three-bit 
messages encoded in tripartite states this decreases to a probability of 1 in 10^^. Arbitrary 
smaller probabilities are achieved exponentially in A^. 

A key aspect of our protocol is rapid implementation of the random unitary matrices, U^, 
at the reference stations. One pragmatic strategy that provides for both a random selection 
mechanism, and the required non-orthogonal behavior between the states |Tj), is to allow 
the Ul to be constructed from random permutations of the Hadamard gate H, and the vr/S 
gate T. It is known that any single- qubi t unitary operation can be approximated to arbitrary 
accuracy from H and T gates {e.g. [23|), and that standard optical devices can be deployed 
to induce such gates on polarized photons. In simulations we have explored permutations 
of the T and H gates as a means of producing the random transforms needed to remove 
the orthogonality of the original basis. A series of random permutations leading to gates 
of the form TTHTHHTTH.... were performed, and the average orthogonality of the set 
|Tj) measured. It was found that even with gates using only 5 random combinations (e.g. 
THHTH) the required non-orthogonal properties between the states |Tj) was achieved - 
with the average fidelity between any two states being F ~ 0.3. Similar fidelities were found 
using the random matrix formulation of Eq. ([2]) . 

The new quantum protocol we have outlined is aimed at networks in which the quantum 
channel utilizes fiber and the classical channel utilizes wireless communications. The proto- 
col requires the use of random transformations at the reference stations, and the presence of 



efficient millisecond quantum memory at the receiver (see 2j] for state-of-the-art implemen- 
tation of quantum memory at telecommunication wavelengths). However, implementation 
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of our protocol is simpler when it is assumed that qubits in the quantum channel move with 
velocity c, as no additional transformations are required, and the need for quantum memory 
is negated (in many set-ups). In such a circumstance the one-dimensional verification pro- 
tocol would follow a set-up similar to that utilized in recent experiments on entanglement 
swapping j25|. In 25|, a BSM via linear optics is conducted on a series of entangled photons 
arriving from different synchronized pulsed sources. Coincidence counting is achieved within 
the nanosecond range. Using similar techniques, an implementation of location verification 
over tens of km, to an accuracy of meters is currently possible. Any relaxation of our initial 
assumptions such as zero processing time, will manifest itself in a (determinable) reduction 
in the accuracy of the location being verified. Note that even though we have described our 
protocol under the assumption that all four Bell states can be discriminated in the BSM 
- this is not a requirement. When using linear optics for BSM only two Bells states can 
be discriminated (deterministically). In this case our encoding scheme would need to be 
adjusted to a three message encoding. This has the minor effect of a drop in the channel 
capacity. 

Clearly there are many variants on our protocol, such as the use of teleportation, the use 
of other entanglement degrees of freedom, and the use of entanglement swapping between 
the reference stations and the device. For example, a modified verification protocol that uses 
entanglement swapping can be constructed that entirely negates the requirement for direct 
transfer of qubits between the reference stations and the device. Location verification would 
then be possible in a satellite-to-device communications system, provided the satellite and 
the device shared a-priori an entangled resource stored in quantum memory. 

Quantum location verification could greatly assist in the authentication of devices within 



large-scale multihop quantum networks 



26| . Current quantum authentication techniques 



require the distribution of secret keys distributed a priori amongst potential users 27 |. 
However, such keys, whether classical bits or entangled qubits, are subject to unauthorized 
re-distribution. We also note that quantum location verification can be used within other 
data-delivery protocols in which real-time data transfer can be communicated to a device 
successfully only if that device is at a specific location. The location verification can be 
monitored continuously in real time, halting any real-time data transfer upon violation 
of the verification procedures. An adversary could not continue to receive real-time data 
without one of his devices being at the specified location. 
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Quantum location verification represents a new application in the emerging field of quan- 
tum communications. It delivers an outcome not possible in the classical-only channel. 
For the first time, we possess the ability to unconditionally authenticate a communication 
channel based on the geographical coordinates of a receiver. 
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